PT-2026-50244 · Undefined · Undefined

Dyingman1

·

Published

2026-06-17

·

Updated

2026-06-17

·

CVE-2026-8383

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The LearnPress WordPress plugin before 4.3.7 does not gate the edit context on one of its REST endpoint behind the edit users capability, allowing unauthenticated visitors to retrieve each returned user's roles, full capabilities map, extra capabilities, locale, and registration date via a crafted request

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8383

Affected Products

Undefined